Only 6% of companies qualify as AI high performers in McKinsey's August 2026 State of AI survey, and 63% report no measurable effect on earnings, despite 80% seeing individual productivity gains (The Register). The 6% did not have better models. They had cleaner data, a process worth automating, someone accountable, and rules about what the AI was allowed to touch. Readiness is the difference, and it can be measured before a dollar is spent on a build.
We run a readiness assessment before every AI engagement, because the alternative is discovering in week six that the data does not exist or nobody can approve the integration. This post is that assessment: 25 checks across five areas, a scoring method, and what each score band means for the first project you should attempt. It is written so you can run it yourself in an afternoon. It does not tell you which AI product to buy; it tells you whether your company can get value from any of them yet, and what to fix first if not.
What is an AI readiness assessment?
An AI readiness assessment is a structured evaluation of whether an organization has the data, processes, people, technology, and governance needed to deploy AI systems that produce measurable business results. It scores each area against concrete criteria, identifies the gaps most likely to cause a project to stall, and recommends a first project matched to the organization's actual readiness rather than its ambition. For small and mid-sized companies it takes a few hours and a handful of interviews, not a consulting engagement.
Why readiness predicts outcomes better than budget
The 2026 data is consistent across sources. IBM's CEO study found only about 25% of AI initiatives delivered expected ROI and just 16% scaled enterprise-wide (IBM). MIT's NANDA project put the share of generative AI pilots with no measurable P&L impact at 95% (Fortune). Among small businesses, 58% now use generative AI but only 14% have it embedded in operations (Epiphany Dynamics). And the Cloud Security Alliance found that more than half of organizations cannot even produce an inventory of the AI systems they run (Cloud Security Alliance).
In our experience the failures trace back to readiness gaps that were visible at the start: a process nobody had measured, data spread across spreadsheets with no owner, an integration that needed a permission nobody would give, or an AI that was deployed with no rule about what it could do. Every one of those is on the checklist below.
The 25-point AI readiness checklist
Score each item 0 (no), 1 (partly), or 2 (yes). Be honest; the score is for you.
Area 1: Data (the area most companies overestimate)
| # | Check | Scores 2 when |
|---|---|---|
| 1 | The data the AI would use exists in a system, not in people's heads or email | You can point to the database, CRM, or document store |
| 2 | It is accessible through an API or export without a special project | An engineer could pull it this week |
| 3 | It is accurate enough that a person trusts it for the same task today | Staff use it as the source of truth, not a starting point |
| 4 | Someone owns it and can say what is in it | A named owner can describe fields, gaps, and history |
| 5 | Personal or sensitive data in it is classified and its use is permitted | You know which fields are PII and have the right to process them for this purpose |
Area 2: Process (the area that decides ROI)
| # | Check | Scores 2 when |
|---|---|---|
| 6 | A specific, repeated process is the target, not "use AI" | You can name the process and who performs it |
| 7 | It has volume: at least hundreds of occurrences a month | Volume is known from a system, not estimated |
| 8 | It has a unit cost or a measurable outcome | Cost per ticket, per document, per lead, or a conversion rate exists |
| 9 | It is documented well enough that a new hire could do it | A written procedure exists and matches reality |
| 10 | Its exceptions are known and bounded | You can list the top ten cases that break the standard path |
Area 3: People
| # | Check | Scores 2 when |
|---|---|---|
| 11 | An executive sponsor owns the outcome and the budget | One person, named, with authority to unblock |
| 12 | A process owner will change how the team works | The manager of the affected team is a participant, not a recipient |
| 13 | Someone technical can own the system after launch | Internal engineer, or a retained partner with named response times |
| 14 | The affected team has been told and asked | Staff know what the AI will and will not do, including about their roles |
| 15 | Time is allocated for review and feedback in the first quarter | Hours per week are budgeted for transcript or output review |
Area 4: Technology
| # | Check | Scores 2 when |
|---|---|---|
| 16 | The systems the AI must read or write have APIs | Documented endpoints, or at least a vendor that supports integration |
| 17 | Identity and access are centrally managed | Single sign-on or a directory; you can grant a scoped service account |
| 18 | Cloud infrastructure exists with someone who can provision it | An account, a billing owner, and a person who can deploy |
| 19 | Logging and monitoring exist for current systems | You find out about outages before customers do |
| 20 | Security basics are in place: MFA, backups tested, secrets managed | A recent restore test and no credentials in code |
Area 5: Governance
| # | Check | Scores 2 when |
|---|---|---|
| 21 | A written AI policy exists covering tools, data, and accountability | Adopted, owned, and read by staff |
| 22 | An inventory of AI already in use exists | Including tools individuals adopted on their own |
| 23 | Rules exist for what an AI system may do without human approval | Irreversible actions require a person |
| 24 | Customer disclosure and regulatory obligations are known | You know whether EU AI Act, state laws, or sector rules apply |
| 25 | A way to measure and report results exists | A baseline metric and a review cadence are agreed before the build |
What your score means
Total the five areas (maximum 10 each, 50 overall). The overall score tells you what kind of project to attempt; the lowest area tells you what to fix first.
| Score band | Readiness | Recommended first project | Fix first |
|---|---|---|---|
| 0 to 19 | Not ready | No build. A 4 to 6 week readiness sprint: pick one process, measure it, find the data, write the policy | Whatever area scored lowest; usually Data or Process |
| 20 to 31 | Ready for a bounded pilot | One read-only or propose-only agent on a single process with a holdout and a 90-day review | Any area under 5; do not build until Governance is at least 5 |
| 32 to 42 | Ready for production | A production agent that acts within limits, with an evaluation suite and monitoring | Close the remaining gaps in Technology before integration starts |
| 43 to 50 | Ready to scale | A portfolio: two or three agents on adjacent processes sharing infrastructure and governance | Nothing blocking; invest in evaluation and cost control |
Two rules override the bands. If Data scores under 4, no build clears the bar regardless of total, because the system will have nothing reliable to work with. If Governance scores under 4, the project may work technically and still be rolled back the first time it does something nobody authorized. The policy that fixes Governance in a week is in our AI governance policy template.
How to run the assessment in an afternoon
- Pick the candidate process first. The assessment is meaningless in the abstract. Choose the one process where an AI result would be most obviously valuable, and score everything against it.
- Interview three people for twenty minutes each. The person who does the process, the person who manages it, and whoever runs the systems it touches. Score Data, Process, and Technology from what they say, not from the org chart.
- Score Governance from documents, not memory. If the policy, inventory, and disclosure analysis cannot be produced as files, they score zero. This is where honest scoring matters most.
- Total, find the lowest area, and write the gap list. Each item scoring 0 or 1 becomes a task with an owner and a date. Most gap lists for a mid-sized company are eight to twelve items and take four to six weeks.
- Match the first project to the band, not the ambition. A company scoring 26 that builds a production agent joins the 63%. The same company running a propose-only pilot for a quarter usually moves into the 32 to 42 band and builds the production system on evidence.
The gaps we see most often, and how long they take to close
- No unit cost for the target process (check 8). Two to four weeks of measurement. Without it there is no ROI model and no way to know if the project worked; the method is in how to measure AI ROI.
- Data in spreadsheets and inboxes (checks 1, 2). Four to eight weeks to consolidate into a system with an owner. Often the most valuable outcome of the whole exercise, AI or not.
- No API on the core system (check 16). Either a vendor conversation, a middleware layer, or a decision to wrap the system, which we cover in legacy system modernization.
- No AI policy or inventory (checks 21, 22). One week with the template. This is the cheapest gap to close and the one most often left open.
- No technical owner after launch (check 13). A retainer with named response times, or an internal hire. Systems without an owner are the ones Sinch's 74% rollback figure describes; we explain why in why AI pilots fail.
Companies that close those gaps typically move up one band in six to eight weeks. That is faster than most AI builds, and it is why we insist on running the assessment first: a build on a readiness score of 35 ships and pays back; the same build on a score of 22 becomes a lesson.
What happens after the assessment
For most mid-sized companies the answer is a bounded first project: one process, one metric, one agent that reads or proposes rather than acts, a holdout group, and a 90-day review. If you have not yet chosen the process, AI automation for small business walks through the candidates, and our AI development services buyer's guide explains what each type of build involves and costs. When the readiness score supports production, the vendor questions in how to choose an AI agent development company come next, and the security controls the build must include are in the AI agent security checklist.
Frequently asked questions
What is included in an AI readiness assessment?
Five areas: data (does the data exist, is it accessible, accurate, owned, and permitted), process (is there a specific, high-volume process with a unit cost and known exceptions), people (sponsor, process owner, technical owner, team buy-in, review time), technology (APIs, identity, cloud, monitoring, security basics), and governance (policy, inventory, action rules, disclosure obligations, measurement). Each is scored and the lowest area sets the first priority.
How long does an AI readiness assessment take?
For a small or mid-sized company assessing one candidate process, an afternoon: three twenty-minute interviews, a review of governance documents, and scoring. Closing the typical gap list takes four to eight weeks. Enterprise-wide assessments across many processes and business units take longer and are a different exercise.
What AI readiness score do we need before building?
On the 50-point checklist in this post, 32 or above for a production agent that takes actions, 20 to 31 for a bounded read-only or propose-only pilot, and below 20 means a readiness sprint before any build. Data below 4 or Governance below 4 blocks a build regardless of the total.
Why do AI projects fail even with good technology?
Because readiness gaps that were visible at the start were not addressed: no measured baseline, data nobody owns, integrations nobody can approve, no rule about what the AI may do, and no one accountable after launch. McKinsey's 2026 data shows 80% of companies see productivity gains and 63% see no earnings impact; the gap is readiness, not model quality.
Can we run the assessment ourselves?
Yes; the checklist above is designed for it. The value of an outside assessor is honesty on Data and Governance, where internal scoring tends to be generous, and experience matching the score to a first project of the right size. Either way, the score should exist before the budget does.
Key takeaways
- Only 6% of companies are AI high performers and 63% see no earnings impact. Readiness, not model quality, separates them.
- Twenty-five checks across data, process, people, technology, and governance, scored 0 to 2, give a 50-point readiness score in an afternoon.
- Under 20: readiness sprint, no build. 20 to 31: bounded pilot. 32 to 42: production agent. 43 and above: scale.
- Data under 4 or Governance under 4 blocks any build, whatever the total.
- The most common gaps are a missing unit cost, data in spreadsheets, no API, no policy, and no technical owner. Most close in four to eight weeks.
- Match the first project to the score, not the ambition. Moving up a band first is faster than building twice.
Get your readiness score, scored by someone who has to live with it
If you want an outside score, tell us the process you have in mind and we will run the 25-point assessment with you in a single working session, at no charge, and send a written score with a gap list and a recommended first project. We do it free because we build the projects that follow, and we would rather build one that is ready. If the score says wait, we will tell you what to fix and come back when it is done; that is the standard our AI development practice holds itself to.
Sources
- The Register: McKinsey State of AI 2026 findings
- IBM: 2026 CEO Study
- Fortune: MIT report on generative AI pilot outcomes
- Epiphany Dynamics: State of AI adoption in US small business 2026
- Capsule: Small business AI adoption statistics
- Cloud Security Alliance: AI inventory and EU AI Act readiness findings
- Sinch: The AI Production Paradox
